Linwei Ding, the former Google software engineer convicted of stealing AI trade secrets and passing them to Chinese companies, has had part of that conviction thrown out, according to a court ruling reported by Techmeme. The case has stood as one of the most closely watched insider-threat prosecutions in AI since Ding's arrest, precisely because it tested how far criminal trade-secret law reaches when the stolen material is model architecture and infrastructure code rather than a physical blueprint.

Ding worked at Google on software tied to the company's custom AI accelerator stack — the kind of internal tooling that sits underneath large-scale model training and is rarely discussed publicly. Prosecutors alleged he copied a large volume of confidential technical files to a personal account while secretly involved with AI ventures based in China. A jury convicted him; the court has now scaled part of that verdict back, though the core finding of guilt has not been erased.

According to Techmeme, the partial reversal doesn't clear Ding — it narrows the outcome. That distinction matters for anyone watching this case as a signal for how AI IP theft gets prosecuted going forward.

Why this case became a bellwether

Trade-secret law was written for physical formulas, manufacturing processes, and customer lists. Applying it to AI systems raises questions courts are still working through: what exactly counts as the protected secret when the material in question is a combination of infrastructure code, hardware-software integration details, and know-how that's partly documented and partly tacit? A conviction is one thing; getting every count and every underlying claim to survive appellate scrutiny is another. Partial reversals in cases like this are common precisely because prosecutors often charge broadly — multiple counts, multiple theories of harm — and only some of that breadth holds up.

For AI labs, the practical lesson isn't about this specific defendant. It's that the legal system treating model infrastructure as a trade secret is still a live, evolving question rather than settled law labs can fully rely on for protection.

The actual insider-threat pattern here

Strip away the legal outcome and the underlying facts describe a pattern security teams at AI labs should recognize:

This is the standard shape of AI IP theft: not a sophisticated external breach of a model's weights, but an insider with normal access rights moving data through channels — personal cloud storage, USB drives, personal email — that sit outside most companies' monitoring.

What builders should actually take from this

The headline risk in AI security discourse tends to be external — jailbreaks, prompt injection, model extraction via API abuse. Insider exfiltration gets less airtime but is arguably the more direct threat to the IP labs actually care about protecting: training infrastructure, unreleased architectures, and proprietary tooling. A few practical takeaways for teams building or scaling AI infrastructure:

AiiN's takeaway

The lesson here isn't about Ding specifically or the legal fine print of his appeal. It's that insider exfiltration of AI infrastructure IP is a real, recurring threat, and the legal system's response to it — even when a jury has already ruled — remains unsettled enough that labs can't treat prosecution as sufficient protection. In our estimation, the labs least exposed to this kind of loss are the ones that already assume court outcomes will be partial, slow, and uncertain, and build technical and process controls accordingly rather than leaning on the threat of prosecution alone.